Atlassian Jira Server SSRF Vulnerability (CVE-2019-8451)
CVE-2019-8451 is an unauthenticated Server-Side Request Forgery (SSRF) vulnerability in the Atlassian Jira Server gadgets servlet that allows attackers to access internal network resources.
CVE search metadata
CVE search record: CVE-2019-8451. Severity: medium. CVSS: 6.5. EPSS: 94.45%. KEV: no. Product: Jira Server (< 8.4.0). Brief: Atlassian Jira Server SSRF Vulnerability (CVE-2019-8451). Brief link: https://feed.craftedsignal.io/briefs/2026-09-cve-2019-8451/
CVE-2019-8451 is a Server-Side Request Forgery (SSRF) vulnerability affecting Atlassian Jira Server versions prior to 8.4.0. The vulnerability exists within the /plugins/servlet/gadgets/makeRequest endpoint, which fails to correctly validate the target URL provided in the request parameter. A logic error within the JiraWhitelist class allows an unauthenticated remote attacker to bypass intended security controls and force the Jira server to initiate HTTP requests to arbitrary internal or external network resources. This flaw can be weaponized to conduct reconnaissance of internal services, interact with private APIs, or exfiltrate sensitive data reachable from the Jira server's network segment. The public availability of functional exploit code increases the risk of exploitation for organizations that have not yet upgraded their Jira instances to the patched version, 8.4.0 or later.
Attack Chain
- The attacker performs network reconnaissance to identify internet-facing Jira Server instances.
- The attacker sends a crafted HTTP GET or POST request to the target's /plugins/servlet/gadgets/makeRequest endpoint.
- The attacker injects a target URL into the 'url' query parameter of the request.
- The Jira Server's gadgets servlet processes the request and passes the URL to the flawed JiraWhitelist class for validation.
- Due to the logic bug, the validator fails to identify or block the malicious URL destination.
- The Jira Server executes an outbound request to the attacker-supplied URL on behalf of the server.
- The server receives the response from the internal resource and returns the content of that resource to the attacker in the HTTP response body.
- The attacker parses the response to discover internal network infrastructure or exfiltrate sensitive internal service data.
Impact
Successful exploitation allows unauthenticated attackers to bypass network perimeter security, conduct internal network discovery, and access sensitive data hosted on internal services that are not directly exposed to the internet. While the vulnerability does not directly grant Remote Code Execution (RCE) on the Jira host, it provides a powerful primitive for lateral movement and further exploitation of the internal environment.
Recommendation
Prioritized actions for security teams:
- Upgrade all instances of Atlassian Jira Server to version 8.4.0 or later to remediate the logic flaw in JiraWhitelist.
- Deploy detection rules to monitor for suspicious requests to the gadgets servlet as outlined below.
- Review web server access logs for anomalous traffic targeting the /plugins/servlet/gadgets/makeRequest path, especially those with outbound-looking URLs in the query string.
- Implement egress filtering on the host running Jira to restrict the server from initiating unauthorized connections to sensitive internal subnets.
Immediate actions
Upgrade Jira Server to version 8.4.0 or later.
Mitigations
Upgrade Jira Server to 8.4.0
CVE-2019-8451
Detection coverage 1
Detects CVE-2019-8451 Exploitation - SSRF via gadgets servlet
highDetects exploitation attempts against CVE-2019-8451 by monitoring for requests to the gadgets makeRequest endpoint containing potentially malicious target URLs.
Detection queries are available on the platform. Get full rules →